<?xml version="1.0" encoding="US-ASCII"?>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt"?>
<!DOCTYPE rfc SYSTEM 'rfc2629.dtd'>
<?rfc toc="yes"?>
<?rfc compact="yes"?>
<?rfc subcompact="no"?>
<?rfc symrefs="yes" ?>
<?rfc sortrefs="yes"?>
<?rfc iprnotified="no"?>
<?rfc strict="yes"?>
<rfc number="7895" ipr="trust200902" category="std" submissionType="IETF" consensus="yes" >
    <front>
    <title abbrev="YANG Library">YANG Module Library</title>

    <author initials="A" surname="Bierman" fullname='Andy Bierman' >
      <organization>YumaWorks</organization>
      <address>
        <email>andy@yumaworks.com</email>
      </address>
    </author>
    <author initials="M" surname="Bjorklund" fullname='Martin Bjorklund' >
      <organization>Tail-f Systems</organization>
      <address>
        <email>mbj@tail-f.com</email>
      </address>
    </author>
    <author initials="K" surname="Watsen" fullname='Kent Watsen' >
      <organization>Juniper Networks</organization>
      <address>
        <email>kwatsen@juniper.net</email>
      </address>
    </author>
	<date month="June" year="2016"/>


<keyword>NETCONF</keyword>
<keyword>RESTCONF</keyword>


    <abstract>
	<t>
This document describes a YANG library that provides information
about all the YANG modules used by a network management server (e.g.,
a Network Configuration Protocol (NETCONF) server).  Simple caching
mechanisms are provided to allow clients to minimize retrieval of this
information.
	</t>
</abstract>
</front>
<middle>
<section title="Introduction">
    <t>
There is a need for standard mechanisms to identify the YANG modules
and submodules that are in use by a server that implements YANG data
models.  If a large number of YANG modules are utilized by the server,
then the YANG library contents needed can be relatively large.  This
information changes very infrequently, so it is important that clients
be able to cache the YANG library contents and easily identify whether
their cache is out of date.
    </t>
    <t>
YANG library information can be different on every server
and can change at runtime or across a server reboot.
    </t>
    <t>
If the server implements multiple protocols to access the
YANG-defined data, each such protocol has its own conceptual
instantiation of the YANG library.
    </t>
    <t>
The following information is needed by a client application
(for each YANG module in the library)
to fully utilize the YANG data modeling language:
    </t>
<t>
 <list style="symbols">
 <t>
name: The name of the YANG module.
 </t>
 <t>
revision: Each YANG module and submodule within the library
has a revision.  This is derived from the most
recent revision statement within the module or submodule.  If no such
revision statement exists, the module&apos;s or submodule&apos;s revision is the
zero-length string.
 </t>
 <t>
submodule list: The name and revision of each submodule
used by the module MUST be identified.
 </t>
 <t>
feature list: The name of each YANG feature supported by the
server MUST be identified.
 </t>
 <t>
deviation list: The name of each YANG module used for deviation
statements MUST be identified.
 </t>
 </list>
</t>
<section title="Terminology">
    <t>
The keywords &quot;MUST&quot;, &quot;MUST NOT&quot;, &quot;REQUIRED&quot;, &quot;SHALL&quot;, &quot;SHALL NOT&quot;,
&quot;SHOULD&quot;, &quot;SHOULD NOT&quot;, &quot;RECOMMENDED&quot;, &quot;NOT RECOMMENDED&quot;, &quot;MAY&quot;, and
&quot;OPTIONAL&quot; in this document are to be interpreted as described in BCP
14, <xref target="RFC2119"/>.
    </t>
    <t>
The following terms are defined in <xref target="RFC6241"/>:
    </t>


<t>
 <list style="symbols">
 <t>
client
 </t>
 <t>
server
 </t>
 </list>
</t>
    <t>
The following terms are defined in <xref target="YANG1.1"/>:
    </t>
<t>
 <list style="symbols">
 <t>
module
 </t>
 <t>
submodule
 </t>
 </list>
</t>
    <t>
The following terms are used within this document:
    </t>
<t>
 <list style="symbols">
 <t>
YANG library: A collection of YANG modules and submodules
used by a server.
 </t>
 </list>
</t>
</section>
<section title="Tree Diagrams">
    <t>
A simplified graphical representation of the data model is used in
this document.  The meaning of the symbols in these
diagrams is as follows:
    </t>
<t>
 <list style="symbols">
 <t>
Brackets &quot;[&quot; and &quot;]&quot; enclose list keys.
 </t>
 <t>
Abbreviations before data node names: &quot;rw&quot; means configuration
data (read-write) and &quot;ro&quot; state data (read-only).
 </t>
 <t>
Symbols after data node names: &quot;?&quot; means an optional node, &quot;!&quot; means
a presence container, and &quot;*&quot; denotes a list and leaf-list.
 </t>
 <t>
Parentheses enclose choice and case nodes, and case nodes are also
marked with a colon (&quot;:&quot;).
 </t>
 <t>
Ellipsis (&quot;...&quot;) stands for contents of subtrees that are not shown.
 </t>
 </list>
</t>
</section>
</section>
<section title="YANG Module Library">
    <t>
The &quot;ietf&#8209;yang&#8209;library&quot; module provides information about
the YANG library used by a server. This module is defined
using YANG version 1, but it supports the description of YANG modules
written in any revision of YANG.
    </t>
    <t>
Following is the YANG Tree Diagram for the &quot;ietf&#8209;yang&#8209;library&quot; module:</t>
<figure><artwork><![CDATA[
   +--ro modules-state
      +--ro module-set-id    string
      +--ro module* [name revision]
         +--ro name                yang:yang-identifier
         +--ro revision            union
         +--ro schema?             inet:uri
         +--ro namespace           inet:uri
         +--ro feature*            yang:yang-identifier
         +--ro deviation* [name revision]
         |  +--ro name        yang:yang-identifier
         |  +--ro revision    union
         +--ro conformance-type    enumeration
         +--ro submodule* [name revision]
            +--ro name        yang:yang-identifier
            +--ro revision    union
            +--ro schema?     inet:uri
]]></artwork>
</figure>
<section title="modules-state">
    <t>
This mandatory container holds the identifiers
for the YANG data model modules supported by the server.
    </t>
<section title="modules-state/module-set-id">
    <t>
This mandatory leaf contains a unique implementation-specific
identifier representing the current set of modules and submodules
on a specific server.
The value of this leaf MUST change whenever the set of modules and
submodules in the YANG library changes.  There is no requirement that
the same set always results in the same "module-set-id" value.
    </t>
    <t>
This leaf allows a client to fetch the module list once, cache
it, and only refetch it if the value of this leaf has been
changed.
    </t>
    <t>
If the value of this leaf changes, the server also generates a
&quot;yang&#8209;library&#8209;change&quot; notification, with the new value of
&quot;module&#8209;set&#8209;id&quot;.
    </t>
    <t>
Note that for a NETCONF server that implements YANG 1.1
<xref target="YANG1.1"/>, a change of the &quot;module&#8209;set&#8209;id&quot; value
results in a new value for the :yang-library capability defined in
<xref target="YANG1.1"/>.  Thus, if such a server implements
NETCONF notifications <xref target="RFC5277"/>, and the notification
&quot;netconf&#8209;capability&#8209;change&quot; <xref target="RFC6470"/>, a &quot;netconf&#8209;capability&#8209;change&quot;
notification is generated whenever the &quot;module&#8209;set&#8209;id&quot; changes.
    </t>
</section>
<section title="modules-state/module">
    <t>
This mandatory list contains one entry
for each YANG data model module supported by the server.
There MUST be an entry in this list for each revision
of each YANG module that is used by the server.
It is possible for multiple revisions of the same module
to be imported, in addition to an entry for the revision
that is implemented by the server.
    </t>
</section>
</section>
<section title="YANG Library Module" anchor="library-module">


    <t>
The &quot;ietf&#8209;yang&#8209;library&quot; module defines monitoring
information for the YANG modules used by a server.
    </t>
    <t>
The &quot;ietf&#8209;yang&#8209;types&quot; and &quot;ietf&#8209;inet&#8209;types&quot; modules from <xref target="RFC6991"/>
are used by this module for some type definitions.
    </t>

<t>&lt;CODE BEGINS> file "ietf-yang-library@2016-06-21.yang"</t>
<figure><artwork><![CDATA[
module ietf-yang-library {
  namespace "urn:ietf:params:xml:ns:yang:ietf-yang-library";
  prefix "yanglib";

  import ietf-yang-types {
    prefix yang;
  }
  import ietf-inet-types {
    prefix inet;
  }

  organization
    "IETF NETCONF (Network Configuration) Working Group";

  contact
    "WG Web:   <https://datatracker.ietf.org/wg/netconf/>
     WG List:  <mailto:netconf@ietf.org>

     WG Chair: Mehmet Ersue
               <mailto:mehmet.ersue@nsn.com>

     WG Chair: Mahesh Jethanandani
               <mailto:mjethanandani@gmail.com>

     Editor:   Andy Bierman
               <mailto:andy@yumaworks.com>

     Editor:   Martin Bjorklund
               <mailto:mbj@tail-f.com>

     Editor:   Kent Watsen
               <mailto:kwatsen@juniper.net>";

  description
    "This module contains monitoring information about the YANG
     modules and submodules that are used within a YANG-based
     server.

     Copyright (c) 2016 IETF Trust and the persons identified as
     authors of the code.  All rights reserved.

     Redistribution and use in source and binary forms, with or
     without modification, is permitted pursuant to, and subject
     to the license terms contained in, the Simplified BSD License
     set forth in Section 4.c of the IETF Trust's Legal Provisions
     Relating to IETF Documents
     (http://trustee.ietf.org/license-info).

     This version of this YANG module is part of RFC 7895; see
     the RFC itself for full legal notices.";

  revision 2016-06-21 {
    description
      "Initial revision.";
    reference
      "RFC 7895: YANG Module Library.";
  }

  /*
   * Typedefs
   */

  typedef revision-identifier {
    type string {
      pattern '\d{4}-\d{2}-\d{2}';
    }
    description
      "Represents a specific date in YYYY-MM-DD format.";
  }

  /*
   * Groupings
   */

  grouping module-list {
    description
      "The module data structure is represented as a grouping
       so it can be reused in configuration or another monitoring
       data structure.";

    grouping common-leafs {
      description
        "Common parameters for YANG modules and submodules.";

      leaf name {
        type yang:yang-identifier;
        description
          "The YANG module or submodule name.";
      }
      leaf revision {
        type union {
          type revision-identifier;
          type string { length 0; }
        }
        description
          "The YANG module or submodule revision date.
           A zero-length string is used if no revision statement
           is present in the YANG module or submodule.";
      }
    }

    grouping schema-leaf {
      description
        "Common schema leaf parameter for modules and submodules.";

      leaf schema {
        type inet:uri;
        description
          "Contains a URL that represents the YANG schema
           resource for this module or submodule.

           This leaf will only be present if there is a URL
           available for retrieval of the schema for this entry.";
      }
    }

    list module {
      key "name revision";
      description
        "Each entry represents one revision of one module
         currently supported by the server.";

      uses common-leafs;
      uses schema-leaf;

      leaf namespace {
        type inet:uri;
        mandatory true;
        description
          "The XML namespace identifier for this module.";
      }
      leaf-list feature {
        type yang:yang-identifier;
        description
          "List of YANG feature names from this module that are
           supported by the server, regardless of whether they are
           defined in the module or any included submodule.";
      }
      list deviation {
        key "name revision";
        description
          "List of YANG deviation module names and revisions
           used by this server to modify the conformance of
           the module associated with this entry.  Note that
           the same module can be used for deviations for
           multiple modules, so the same entry MAY appear
           within multiple 'module' entries.

           The deviation module MUST be present in the 'module'
           list, with the same name and revision values.
           The 'conformance-type' value will be 'implement' for
           the deviation module.";
        uses common-leafs;
      }
      leaf conformance-type {
        type enumeration {
          enum implement {
            description
              "Indicates that the server implements one or more
               protocol-accessible objects defined in the YANG module
               identified in this entry.  This includes deviation
               statements defined in the module.

               For YANG version 1.1 modules, there is at most one
               module entry with conformance type 'implement' for a
               particular module name, since YANG 1.1 requires that,
               at most, one revision of a module is implemented.

               For YANG version 1 modules, there SHOULD NOT be more
               than one module entry for a particular module name.";
          }
          enum import {
            description
              "Indicates that the server imports reusable definitions
               from the specified revision of the module but does
               not implement any protocol-accessible objects from
               this revision.

               Multiple module entries for the same module name MAY
               exist.  This can occur if multiple modules import the
               same module but specify different revision dates in
               the import statements.";
          }
        }
        mandatory true;
        description
          "Indicates the type of conformance the server is claiming
           for the YANG module identified by this entry.";
      }
      list submodule {
        key "name revision";
        description
          "Each entry represents one submodule within the
           parent module.";
        uses common-leafs;
        uses schema-leaf;
      }
    }
  }

  /*
   * Operational state data nodes
   */

  container modules-state {
    config false;
    description
      "Contains YANG module monitoring information.";

    leaf module-set-id {
      type string;
      mandatory true;
      description
        "Contains a server-specific identifier representing
         the current set of modules and submodules.  The
         server MUST change the value of this leaf if the
         information represented by the 'module' list instances
         has changed.";
    }

    uses module-list;
  }

  /*
   * Notifications
   */

  notification yang-library-change {
    description
      "Generated when the set of modules and submodules supported
       by the server has changed.";
    leaf module-set-id {
      type leafref {
        path "/yanglib:modules-state/yanglib:module-set-id";
      }
      mandatory true;
      description
        "Contains the module-set-id value representing the
         set of modules and submodules supported at the server at
         the time the notification is generated.";
    }
  }

}
]]></artwork>
</figure>
<t>&lt;CODE ENDS></t>
</section>
</section>
<section title="IANA Considerations" anchor="iana">
<section title="YANG Module Registry">
    <t>
This document registers one URI in the "IETF XML Registry"
<xref target="RFC3688"/>. Following the format in RFC 3688, the following
registration has been made.
    </t>
<figure>
<artwork><![CDATA[
  URI: urn:ietf:params:xml:ns:yang:ietf-yang-library
  Registrant Contact: The NETCONF WG of the IETF.
  XML: N/A, the requested URI is an XML namespace.
]]></artwork>
</figure>
    <t>
This document registers one YANG module in the "YANG Module Names"
registry <xref target="RFC6020"/>.
    </t>
<figure>
<artwork><![CDATA[
  name:         ietf-yang-library
  namespace:    urn:ietf:params:xml:ns:yang:ietf-yang-library
  prefix:       yanglib
  reference:    RFC 7895
]]></artwork>
</figure>
</section>
</section>
<section title="Security Considerations">

<!-- [rfced]  Please note that we have updated the second sentence in the
Security Considerations section to match the boilerplate at
https://trac.tools.ietf.org/area/ops/trac/wiki/yang-security-guidelines. Please
review and let us know any objections.

Original
   Authorization for access to specific
   portions of conceptual data and operations within this module is
   provided by the NETCONF access control model (NACM) [RFC6536].

Updated (per boilerplate)
   The NETCONF access control model
   [RFC6536] provides the means to restrict access for particular
   NETCONF users to a pre-configured subset of all available NETCONF
   protocol operations and content.
-->

    <t>
The YANG module defined in this memo is designed to be accessed
via the NETCONF protocol <xref target="RFC6241"/>.  The lowest NETCONF layer is
the secure transport layer and the mandatory-to-implement secure
transport is SSH <xref target="RFC6242"/>.  
The NETCONF access control model <xref target="RFC6536"/> provides the means to restrict
access for particular NETCONF users to a pre-configured subset of all
available NETCONF protocol operations and content. </t>

    <t>
Some of the readable data nodes in this YANG module may be
considered sensitive or vulnerable in some network environments.
It is thus important to control read access (e.g., via get,
get-config, or notification) to these data nodes.  These are the
subtrees and data nodes and their sensitivity/vulnerability:
    </t>
<t>
 <list style="symbols">
 <t>
/modules-state/module: The module list used in a server
implementation may help an attacker identify the server capabilities
and server implementations with known bugs.
Although some of this information may
be available to all users via the NETCONF &lt;hello&gt; message (or similar
messages in other management protocols), this YANG module potentially
exposes additional details that could be of some assistance to an
attacker. Server vulnerabilities may be
specific to particular modules, module revisions, module features,
or even module deviations.  This information is included in each module entry.
For example, if a particular operation on a particular data node is
known to cause a server to crash or significantly degrade device performance,
then the module list information will help an
attacker identify server implementations with such a defect, in order
to launch a denial-of-service attack on the device.
 </t>
 </list>
</t>
</section>
</middle>
<back>


<references title="Normative References">

<?rfc include="reference.RFC.2119"?>

<?rfc include="reference.RFC.3688"?>

<?rfc include="reference.RFC.6020"?>

<?rfc include="reference.RFC.6241"?>

<?rfc include="reference.RFC.6242"?>

<?rfc include="reference.RFC.6991"?>

<?rfc include="reference.RFC.6536"?>

</references>

<references title="Informative References">


<!-- I-D.ietf-netmod-rfc6020bis IESG state: Approved-announcement to be sent::Point Raised - writeup
needed -->

<reference anchor="YANG1.1">
  <front>
    <title>The YANG 1.1 Data Modeling Language</title>
    <author initials="M" surname="Bjorklund" fullname="Martin Bjorklund">
      <organization/>
    </author>
    <date month="April" day="28" year="2016"/>
  </front>
  <seriesInfo name="Work in Progress," value="draft-ietf-netmod-rfc6020bis-12"/>
  <format type="TXT" target="http://www.ietf.org/internet-drafts/draft-ietf-netmod-rfc6020bis-12.txt"/>
</reference>

<?rfc include="reference.RFC.5277"?>

<?rfc include="reference.RFC.6470"?>

</references>

<section title="Acknowledgements" numbered="no">
    <t>
Contributions to this material by Andy Bierman are based upon work
supported by the Space &amp; Terrestrial Communications Directorate
(S&amp;TCD) under Contract No.&nbsp;W15P7T-13-C-A616. Any opinions, findings, conclusions, or recommendations expressed in this material are
those of the author(s) and do not necessarily reflect the views of
the Space &amp; Terrestrial Communications Directorate (S&amp;TCD).
    </t>
</section>
</back></rfc>
